How to Find Microsoft Graph IP Address Ranges for Firewall Allowlisting
Question details
IT administrators need to identify the correct destination IP address ranges for Microsoft Graph to properly configure network firewall allowlists and ensure secure traffic.

- Product
- Microsoft Graph
- Device & OS
- not provided
- Scenario
- Configuring corporate network firewalls or security appliances to securely allow outbound traffic to Microsoft Graph cloud services.
- Observed behavior
- Network traffic to Microsoft Graph applications may be blocked or dropped if specific IP ranges or service tags are not correctly updated in the firewall rules.
Before updating your firewall rules, ensure you have administrative access to your network security appliance and understand that cloud service IP addresses are dynamic and frequently updated.
Utilize Official Microsoft Service Tags and Endpoint Documentation
The most reliable method to manage dynamic cloud IPs is using Microsoft's published JSON files for Office 365 endpoints or Azure Service Tags instead of hardcoding IPs.
Because Microsoft Graph spans multiple regions and data centers globally, its IP addresses are not static. Hardcoding individual IP addresses is not recommended, as they can change without notice and break service connectivity.
Instead, Microsoft provides regularly updated service tags and endpoint documentation that network administrators should use for configuring allowlists automatically.
Navigate to the official Microsoft documentation portal for Office 365 URLs and IP address ranges.
Locate and download the latest published JSON file containing the updated endpoints and service tags for your specific Microsoft 365 environment.
Import the service tags or JSON data into your firewall management system. Many modern firewalls support automated polling of these lists to keep rules up-to-date automatically.

Seek Specific Guidance in the Microsoft Graph Community
If you have complex routing, strict corporate firewall constraints, or environment-specific requirements, consulting the official community can provide tailored solutions.
Need a Lightweight, Secure Office Suite? Try WPS Office
While managing complex cloud network policies for Microsoft 365, you might also need a fast, locally installable office suite that minimizes heavy cloud dependencies. WPS Office offers a free, lightweight alternative with offline capabilities, high compatibility, and a familiar interface.

Frequently Asked Questions
Are Microsoft Graph IP addresses static?
No, Microsoft Graph IP addresses are dynamic. They are distributed across various global data centers and change over time to optimize routing and load balancing. Administrators should use automated service tags rather than hardcoding static IPs.
How often does Microsoft update its IP ranges and service tags?
Microsoft generally publishes updates to its Office 365 and Azure IP address ranges at the end of each month. However, out-of-band updates can occur, which is why automated retrieval of these lists is highly recommended.
What is the best practice for allowlisting Microsoft Graph on strict firewalls?
The best practice is to allowlist by Fully Qualified Domain Names (FQDNs) if your firewall supports URL filtering. If IP-based rules are strictly required by your security policy, utilize the regularly updated Azure Service Tags or Microsoft 365 endpoint JSON lists.




